# OWASP Recommends DevSecOps Gates

OWASP’s DevSecOps guidance describes voluntary CI/CD security gates for secure software delivery, including blocking new high-risk findings, verifying that scanners run, pinning tools, and documenting time-limited exceptions. It creates no federal procurement mandate, appropriation, or compliance deadline, so contractors can use it as an operational reference rather than a government compliance requirement.

- Contractors can assess whether these practices fit their software delivery pipelines, including workflows using GitHub or GitLab and scanning tools such as Semgrep, Trivy, and Checkov.
- Procurement professionals may use the guidance as a reference when discussing software supply-chain security practices with suppliers, while distinguishing voluntary guidance from binding solicitation or contract requirements.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 06, 2026

### Government Entities
- National Institute of Standards and Technology (NIST)

### Vendors
- GitHub ()
- GitLab ()
- Semgrep ()
- Trivy ()
- Checkov ()

### Sources
- [Security Gates - OWASP DevSecOps Guideline](https://owasp.github.io/DevSecOpsGuideline/2-Process/2-3-Build/2-3-5-Security-Gates) - GitHub